11 ms·
New 'unremovable' xHelper malware has infected 45,000 Android devices
- redm 7y agoI know IOS isn't perfect, however, when I read articles like this, I just have to smile. There's something to be said for a tightly controlled platform and ecosystem.
- benologist 7y agoWhat do you think iOS reviewers were thinking when carefully auditing these apps - https://mashable.com/2017/06/12/apple-app-store-subcription-scams/ https://mashable.com/2017/06/12/apple-app-store-subcription-... https://9to5mac.com/2019/10/25/malware-iphone-apps/ https://9to5mac.com/2019/10/25/malware-iphone-apps/ https://www.techtimes.com/articles/235985/20181204/apple-removes-malicious-fitness-apps-that-tricked-users-to-make-touch-id-payments.htm https://www.techtimes.com/articles/235985/20181204/apple-rem... https://www.wired.com/2015/09/apple-removes-300-infected-apps-app-store/ https://www.wired.com/2015/09/apple-removes-300-infected-app... They get so much wrong, so often, you have to wonder if they really look at the apps at all or just have some checklist, screenshots and a quota to hit. They explicitly approved all the garbage practices that Apple Arcade's billing protects users from.
- simlevesque 7y ago> just have some checklist, screenshots and a quota to hit From my own app review experience, this is all they do.
- dkonofalski 7y agoThat doesn't feel like the same thing at all. A shady developer tricking people into a subscription because they don't know any better is way different from malware that reinstalls itself even after a factory reset. People have to agree to pay for the subscription from an OS-level prompt in the first instance. They don't have a choice in the 2nd.
- ikt 7y ago> A shady developer tricking people into a subscription because they don't know any better is way different from malware that reinstalls itself even after a factory reset. A shady developer tricking people and a shady website tricking people result in bad things. To get this trojan I'd need to go into settings and tick this box: https://q3fb03rfy3f4ahuzu2uy6e11-wpengine.netdna-ssl.com/wp-content/uploads/2016/03/sideload-android-apps.png https://q3fb03rfy3f4ahuzu2uy6e11-wpengine.netdna-ssl.com/wp-... Then go to the dodgy website, then download the apk, then install it then pikachu face when I get a trojan. And you can talk about how great Apple's security is but to fix this issue all Google has to do is remove that tick box in settings so no more sideloading apps. But that also comes back with drawbacks that I assume an Apple user like yourself wouldn't know about, because all you know is a walled garden. Sort of like how Chinese people love the fact their internet is censored. So safe, so secure.
- dkonofalski 7y ago>I assume an Apple user like yourself wouldn't know about Yes, truly... because there's no way that someone who uses an iPhone might know about the existence of Android/Windows/Linux/macOS or any other system that allows for sideloading and/or installing un-certed apps. The point is, even if Apple allowed sideloading, there's no way that the iOS sandbox model would allow for what's being described here. The comparison wasn't accurate. Your condescension and ignorance doesn't help that argument at all.
- Aaargh20318 7y ago> And you can talk about how great Apple's security is but to fix this issue all Google has to do is remove that tick box in settings so no more sideloading apps. And yet, they don’t. > But that also comes back with drawbacks that I assume an Apple user like yourself wouldn't know about, because all you know is a walled garden. Funny how Android users keep saying that. I’m an Android developer by profession, which is why I use an iPhone as my personal phone and would never recommend an Android device even to my worst enemy. I’ve seen how the sausage is made and it isn’t pretty. The best thing you can say about Android is that it’s free, which correctly reflects what it’s worth.
- varenc 7y agoThat's different. Apple's capricious app store review policy aside, iOS is so locked down that even a completely malicious sideloaded* iOS app can't dig itself into the system like this. Without a local privilege escalation exploit there's just no way to set up a persistent background service and no way to escape the sandboxing to allow an app to leave a mark on the system after your app is uninstalled. (*a developer can basically sideload any app on their iOS device with an Apple developer license)
- deleted 7y ago[deleted]
- elliekelly 7y agoIf shady devs can get a malicious app past Apple they can definitely get one past the average user. Does Apple get it right 100% of the time? Of course not. Does Apple get it right far more often than I would? Without a doubt.
- rurp 7y agoGetting a malicious app past Apple in this context might mean as little as getting past a cursory review from a single indifferent employee. Apple has let enough bad apps through that, without further information, my default assumption is that the reviewer is doing little more than checking some boxes.
- bobviolier 7y agoTo be fair, if you stick to just using the Google Play Store, _this_ malware wouldn't hit you. > According to Malwarebytes, the source of these infections is "web redirects" that send users to web pages hosting Android apps. These sites instruct users on how to side-load unofficial Android apps from outside the Play Store. Code hidden in these apps downloads the xHelper trojan.
- hello_friendos 7y agoMaybe not this malware, but there is other malware on the Play Store. https://www.digitaltrends.com/mobile/google-play-store-malware-hits-42-apps-with-8-million-downloads/ https://www.digitaltrends.com/mobile/google-play-store-malwa...
- stjohnswarts 7y agoOf course there is, just like on the Apple web store.
- afro88 7y agoLinks please
- zik 7y agoThere are some just above in this thread.
- dkonofalski 7y agoThose aren't links to malware. Those are links to stories about malware that was removed from the App Store. Kinda makes the opposite point of what you're implying, doesn't it?
- Godel_unicode 7y agohttps://www.wired.com/story/apple-app-store-malware-click-fraud/ https://www.wired.com/story/apple-app-store-malware-click-fr... https://us.norton.com/internetsecurity-emerging-threats-ios-malware-xcodeghost-infects-millions-of-apple-store-customers.html https://us.norton.com/internetsecurity-emerging-threats-ios-...
- dclusin 7y agoIt seems like they could get a better outcome by having levels of trust for unsanctioned apps. Like the default for side-loaded apps would be just as an app only. No background processing, notifications, loading services. To get the latter functionality you could make the user jump through a bunch of hoops with nasty warning messages or even just not allow it.
- m4rtink 7y agoNote that if you enforce this for all side loaded apps are turning Android closer to the walled garden that is iOS. There are already many legitimate apps distributed outside of Google Play for various reasons, such as weird Google policies or simply being booted out with no or spurious reason & the developer not being able to ever reach a human to fix this. So be careful what you wish for.
- dclusin 7y agoI wish apple would allow side loaded apps. I'm not saying eliminate side loaded apps all together. Merely, it seems like its a binary view. Either allow side loaded apps and make no attempt to design the installation process with security features, or deny un-approved applications entirely in the name of security. I think Apple's desktop solution to unverified developers is a good way to split the difference. Deny by default but allow whitelisting. They go even further under the privacy tab and only allow certain applications permission to access accessibility features or full disk access, etc.
- jabbany 7y agoThis actually seems broadly similar to the issue with "self-XSS" and the developer console in browsers (which is hidden behind a couple of menus). So far most of the mitigations involve the site printing messages into the console telling users to not paste in anything here unless they are a developer. Maybe it's a good idea to hide the "Allow sideloaded apps" under the developer menu in Android or something, or generally to display a scarier message.
- 7y ago
- GetOutOfBed 7y agoAre you smiling because people who chose other options than you are having issues?
- tinus_hn 7y agoThe people who made choices that enable these issues, while complaining about other options that prevent these issues?
- jessaustin 7y agoOne needn't badmouth iOS in order to use Android. Indeed, many who use Android don't know that iOS exists.
- aloknnikhil 7y agoOr cannot afford an iPhone. Android brought smartphones to the masses. It's a lack of choice at that price point.
- GetOutOfBed 7y agoI think a large part of "the older generation" doesn't even understand that smartphones have software running on them called "android". My mom calls her Samsung Galaxy "iphone".
- ActorNightly 7y agoSure, except that once you get past the idea of trusting others for your security, and instead learning and securing stuff yourself, you quickly realize that "tightly controlled" is just a synonym for "you don't really own your device, we just let you use it how we see fit". As so recently demonstrated by Apples ability to remove the HKmap.live app. In general really wonder why people still defend Apple these days. Even if you overlook a combination of stuff like infinite attempts for icloud logins that led to the Fappening, their role in HK protests, and of course their pretty terrible labor practices that go so far as even to supposedly break the Chinese labor laws (which is a feat in itself), there is still issues with stuff they produce. Their hardware and software quality has been on a hard decline, especially if you compare it to alternatives rather than on its own merit. They don't really innovate despite opposite marketing claims, and they still participate in this "technology as a jewelry" thing with their $1000 monitor stands.
- scarface74 7y agoSo how do you “secure yourself” - besides having a device that runs an OS that doesn’t allow these types of exploits in the first place?
- jackewiehose 7y agoInstalling custom software is neither an exploit nor a type of it.
- scarface74 7y agoAre you saying that people meant to install the malware?
- jackewiehose 7y agoThey certainly didn't know it was malware but yes, according to the article they installed the software intentionally (they even had to do extra steps and follow instructions on a random website to circumvent the google store).
- sekasi 7y agoI don't know why you're being downvoted. You've got a point. There's no perfection in the App Store when it comes to review, but it's an ecosystem that is built around trying to create a sense of control and privacy. Sorry if you don't disagree but I reckon facts overwhelmingly disagree with you if you do. That's not to say in any way ANDROID BAD or anything like that, it's just a broader attack vector that you're up against with Android unless you're a very careful experienced customer. Most people aren't. :/
- jackewiehose 7y agoI didn't downvote but I understand why others did (I would have if it wasn't already grey). It's incredibly frustrating to read these pro-walled-garden-arguments. By the same argument you could say that the people in Hong Kong or elsewhere should just shut up and accept that their leaders will know what's best for them. I worry about a future where these locked-down devices will be the norm for all of us. Don't defend Apple for locking you in. That's ridiculous.
- edmundsauto 7y agoThe analogy isn't useful because you're comparing a government to a corporation.
- jackewiehose 7y agoOf course it's not the same but it comes down to a party that wants to restrict your freedom in order to protect you.
- edmundsauto 7y agoOne crucial difference is whether you can opt-out. Another big difference is the stated intention of the party/entity: i.e. Apple is not a company "of the people, by the people, and for the people". My objection is that it's not that useful to only look at whether a party wants to restrict freedom. Personally, I don't think that's a very useful dimension at all -- I don't consider the existence of a road limiting to my freedom to drive wherever I feel like it.
- paulmd 7y agoWonder if it's written itself into recovery. Or the SIM card/baseband - SIM card in particular usually includes functionality for triggering a sideload of apps (eg for carrier apps), sending notifications, etc into the main SOC so it fits. Maybe the second instance of SIM card malware ever. https://www.youtube.com/watch?v=31D94QOo2gY https://www.youtube.com/watch?v=31D94QOo2gY There are only so many places it can be hiding if it's surviving a factory reset. --Guy who is undoubtedly vastly underestimating the problem given that it's resisted AV vendors for a while
- imglorp 7y agoAV vendors have multiple conflicts of interest and should not be trusted.
- haliax 7y agoCan you elaborate?
- explodingcamera 7y agoStories of bad viruses actually help them
- ggm 7y agoThis only really goes to the "don't entirely trust their statements regarding their product being the only effective barrier" part of the story. Reputable anti-virus companies do have a huge conflict of interest reporting on viruses they find and can tackle, but they also remain an important source of information about viruses. Disreputable anti-virus companies sell product which could be as simple as a "hollywood OS" green stripe animated GIF which says "virus cleaned" for all they really do: they probably install more malware rather than removing any. Also, an anti virus company saying they can't understand how a virus remains infected after removal is interesting.
- diminoten 7y agoYeah and fires "help" firefighters... How uselessly cynical.
- walrus01 7y ago> The ads and notifications redirect users to the Play Store, where victims are asked to install other apps -- a means through which the xHelper gang is making money from pay-per-install commissions. Software publishers which have been proven to be paying out commission money from "bait and install" app links, for things published in the Play Store, should have their entire app and developer profile removed with extreme prejudice.
- dontblink 7y agoHow do you prove this? What if they start randomizing?
- walrus01 7y agoThrough screenshots (and photographs, if needed) of the actual malware running on example devices, or in sandbox environments, or both, and what Play store install pages they're sending people to. I'd certainly hope that there's some team of people at Google doing exactly this already. Also from bulk analysis tools running against known-malware hosting http daemons out on the Internet. Anybody who's used an android phone for a sufficiently long time and visited a few weird places has seen the javascript redirects for scary-looking pages with "CLEAN 581 VIRUSES FROM YOUR PHONE NOW" pages, designed to mimic android or ios system GUI elements. Inevitably accompanied by a link to a play store page.
- catalogia 7y agoSuppose they send you to one of 20 hardcoded applications in the playstore, only one of which is theirs and the other 19 are innocent third parties being used as cover. Do you ban all 20?
- altfredd 7y agoThat's a bold demand, considering that majority of free games in Play Store monetize themselves via partner installs. For all we know, developers of involved apps are paying a "legit" advertising company for installs, and malware authors act as ordinary partners of that company (likely using a bunch of throwaway accounts).
- Twirrim 7y ago45,000 is a trivial number of infections when you consider that there are 2.5bn monthly active Android devices: https://venturebeat.com/2019/05/07/android-passes-2-5-billion-monthly-active-devices/ https://venturebeat.com/2019/05/07/android-passes-2-5-billio... That's what, 0.0018% of devices infected?
- arcticbull 7y agoSo far?
- 40four 7y agoI'm really confused. How is it possible something like this survives a factory reset? To be fair, I have a very limited knowledge of hardware like this, but my assumption is a factory reset should remove EVERYTHING that didn't come on the phone put of the box. Some other comments are questioning weather this is happeneing to 'budget' devices sold by sketchy manufacturers. Would that explain something like this. I sure as hell hope thats not the case on a phone from reputable manufacturer. If I can't wipe everything, including malware from my android device by doing a factory reset, I'm going to throw it in the garbage tomorrow & buy an iPhone.
- mindslight 7y agoAndroid devices have multiple storage partitions. "Factory reset" generally refers to wiping the data partitions, but not the system partitions. It does not mean reflashing the phone's entire storage from an external image as you would expect. I would imagine this malware modifies one of the partitions that is not customarily wiped. And I would expect that doing a proper full reflash from a computer (eg starting from `fastboot flash bootloader ...`) would remove it, assuming it wasn't already baked into that image at the manufacturer.
- 40four 7y agoThanks for explaining!
- hunter2_ 7y agoAnd the "not customarily wiped" partitions are not wiped because they are not customarily writable in the first place. Rooting a phone by a prominent manufacturer requires discovering an exploit which overcomes this write protection. This is why manufacturers try to protect against exploits, and why you probably shouldn't use a second-hand phone that has known exploits, where second-hand means touched by basically anyone in even a seemingly-legitimate supply chain.
- mindslight 7y ago
- tyingq 7y agoSounds big, but likely paltry compared to active Android devices. That said, for other reasons that are more compelling, Apple is killing Google on "captive portal advantages". Google needs to dedicate more resources to both the PlayStore and the Chrome Extension store for many, many, reasons. They are not getting the inflection point of their "automation is fine" approach. In other words, the conclusion is right, but this incident is NOT the selling point. Ad blockers and manifest V3 is a much better research study into their stupidity.
- 43920 7y agoThis doesn't really seem like a detection issue, but more of a design issue that Google needs to fix. Why is an app able to display ads across the system, even when you aren't running it? And how is it even possible for an app to make itself uninstallable?
- tyingq 7y agoThose are good specific examples that I might have missed. Good point. The PlayStore is a train wreck that takes a lot of percentage of revenue from apps and adds little value in return. Just noting that 45,000 users affected IS NOT the PlayStore failure reference story. It's bigger than that. 10 million uBlock Origin Chrome users are soon to be abandoned due to Google's policies. That's way more interesting, and ties the PlayStore issues to the same Chrome Extension issues. Apple is credibly watching out for their customers. Google is credibly watching out for Google. Pretty much unapologetically with little pushback. Personally frustrating for me as I've been a loyal Android user for a long time. Almost ready to switch to an iPhone, despite my unfamiliarity and the much higher price point. Google should pay attention.
- baroffoos 7y ago>Why is an app able to display ads across the system There is a permission on android called "Draw over other apps" which is disabled by default now when you install the app but the app can open a popup asking you to enable it which android warns you against accepting. The valid use cases for this permission is you could have PIP for videos. Yes its pretty bad but its not like any app can just draw adverts over the screen.
- wnevets 7y ago>According to Malwarebytes, the source of these infections is "web redirects" that send users to web pages hosting Android apps. These sites instruct users on how to side-load unofficial Android apps from outside the Play Store. Code hidden in these apps downloads the xHelper trojan. Ok, maybe don't do that?
- Nairus 7y agoYou never had to deal with an untechnical user, had you?
- hans_castorp 7y agoDoes anyone know if any of the hosts lists from blokada (https://blokada.org/ https://blokada.org/) keeps this out?